Sicurezza AI · Configurazione errata

Vulnerabilità del CrewAI Code Interpreter consentono agli agenti di evadere i sandbox

Un Code Interpreter abilitato permette a prompt injection di evadere il sandbox ed eseguire codice. I ricercatori hanno scoperto quattro vulnerabilità collegate in CrewAI: un fallback Docker verso l'unsafe SandboxPython che permette chiamate arbitrarie a livello C, un SSRF negli strumenti di ricerca RAG, un controllo Docker a runtime che attiva il fallback unsafe, e un JSON loader che legge file locali arbitrari. Un attaccante che può influenzare un agente con il Code Interpreter abilitato o con un code-execution flag impostato può concatenare questi bug per evadere il sandbox ed eseguire codice o leggere file sull'host.

1 fonte · 31 mar

CVE-2026-2287

NVD KEV

EPSS 0.7% (52º percentile).

CVE-2026-2285

NVD KEV

EPSS 0.6% (44º percentile).

CVE-2026-2286

NVD KEV

EPSS 0.5% (40º percentile).

CVE-2026-2275

NVD KEV

CVSS 9.6 CRITICAL: the CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through… EPSS 0.4% (35º percentile).

Cronologia

Fonti

Part of the PlainSec briefing for 2026-04-01

Every edition of this story: Vulnerabilità del CrewAI Code Interpreter consentono agli agenti di evadere i sandbox

Altro da oggi